14 unchanged sentences
In addition, we periodically engage third-party consultants to assist us in assessing, enhancing, implementing, and monitoring our cybersecurity risk management programs and responding to any incidents.
−Removed: As part of our cybersecurity risk management process, we conduct “tabletop” exercises during which we simulate cybersecurity incidents to ensure that we are prepared to respond to such an incident and to highlight any areas for potential improvement in our cyber incident preparedness.
+Added: As part of our cybersecurity risk management process, we conduct regular pen-testing and red-teaming to assess the security of our assets as well as “tabletop” exercises during which we simulate cybersecurity incidents to ensure that we are prepared to respond to such an incident and to highlight any areas for potential improvement in our cyber incident preparedness.
In addition, all employees are required to complete a mandatory cybersecurity training course on an annual basis and receive monthly phishing simulations to provide “experiential learning” on how to recognize phishing attempts.
9 unchanged sentences
The Audit Committee is charged with reviewing our cybersecurity processes for assessing key strategic, operational, and compliance risks.
−Removed: Our Chief Information Digital Officer and Senior Vice President, Information Technology & Data Analytics (CIDO) and our Chief Security Officer (CSO) provide presentations to the Audit Committee on cybersecurity risks at each of its bimonthly meetings.
+Added: Our Chief Information Digital Officer and Senior Vice President, Information Digital Technology & Security (CIDO) and our Chief Security Officer (CSO) provide presentations to the Audit Committee on cybersecurity risks at each of its bimonthly meetings.
These briefings include assessments of cyber risks, the threat landscape, updates on incidents, and reports on our investments in cybersecurity risk mitigation and governance.
3 unchanged sentences
The Aerospace Safety Committee provides oversight of the risks from cybersecurity threats related to our aerospace products and services.
−Removed: The Aerospace Safety Committee receives regular updates and reports from senior management, including the Chief Engineer, the Chief Aerospace Safety Officer, and the Chief Product Security Engineer, who provide briefings on significant cybersecurity threats or incidents that may pose a risk to the safe operation of our aerospace products.
−Removed: Both committees brief the full Board on cybersecurity matters discussed during committee meetings , and the CIDO provides annual briefings to the Board on information technology and data analytics related matters, including cybersecurity.
+Added: The Aerospace Safety Committee receives regular updates and reports from senior management, including the Chief Engineer, the Chief Aerospace Safety Officer, and the Chief Product Security Officer, who provide briefings on significant cybersecurity threats or incidents that may pose a risk to the safe operation of our aerospace products.
+Added: Both committees brief the full Board on cybersecurity matters discussed during committee meetings , and the CIDO provides annual briefings to the Board on Information Digital Technology & Security related matters, including cybersecurity.
At the management level, we have established a Global Security Governance Council (the Council) to further strengthen our cybersecurity risk management activities across the Company, including the prevention, detection, mitigation, and remediation of cybersecurity incidents.
The Council is responsible for developing and coordinating enterprise cybersecurity policy and strategy, and for providing guidance to key management and oversight bodies.
−Removed: Trent Cox, Vice President of Product and Business Operations, is serving as our interim CSO.
−Removed: In that role, he chairs the Council and is responsible for overseeing a unified security program that provides cybersecurity, fire and protection operations, physical security, insider threat, and classified security.
−Removed: Cox has over 25 years of experience in the aerospace and defense industry, including, prior to joining Boeing in 2024, Chief Information Officer of Raytheon UK, Deputy CIO and Executive Director of Collins Aerospace and Raytheon Intelligence and Space, and Executive Director for Program Execution for the Raytheon Missile Systems businesses.
+Added: Terry Rice, Chief Security Officer, Vice President of Cybersecurity, chairs the Council and is responsible for overseeing a unified security program that provides cybersecurity, fire and protection operations, physical security, insider threat, and classified security.
+Added: Rice has over 25 years of experience within cybersecurity and technology risk management, including, prior to joining Boeing in 2025, serving as the Chief Information Security Officer at Merck.
+Added: He served on the board of the Health Information Sharing and Analysis Center (H-ISAC) and is a former-chairman of the Healthcare Sector Coordinating Council Cyber Working Group as well as a prior member of the Healthcare Industry Cybersecurity Task Force.
+Added: Rice consulted in a variety of information security roles at Hughes Aircraft and Raytheon before spending four years at Johnson & Johnson as the Director of Global Information Security.
He reports directly to the CIDO and meets regularly with other members of senior management and the Audit Committee.
−Removed: The Council also includes, among other senior executives, our CIDO, Chief Engineer, Chief Information Officer, Chief Aerospace Safety Officer and Chief Product Security Engineer, who each have several decades of business and senior leadership experience managing risks in their respective fields, collectively covering all aspects of cybersecurity, data and analytics, product security engineering, enterprise engineering, safety and the technical integrity of our products and services.
−Removed: The Council meets monthly and updates key members of the Company’s Executive Council on progress towards specific cybersecurity objectives.
−Removed: A strong partnership exists between Information Technology, Enterprise Security, Corporate Audit, and Law so that identified issues are addressed in a timely manner and incidents are reported to the appropriate regulatory bodies as required.
+Added: The Council also includes, among other senior executives, our CIDO, Chief Engineer, Chief Aerospace Safety Officer and Chief Product Security Officer, who each have several decades of business and senior leadership experience managing risks in their respective fields, collectively covering all aspects of cybersecurity, data and analytics, product security engineering, enterprise engineering, safety and the technical integrity of our products and services.
+Added: The Council meets regularly and updates key members of the Company’s Executive Council on progress towards specific cybersecurity objectives.
+Added: A strong partnership exists between Information Digital Technology & Security, Corporate Audit, and Law so that identified issues are addressed in a timely manner and incidents are reported to the appropriate regulatory bodies as required.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.